A firewall is a network security control that monitors and filters incoming and outgoing traffic according to a defined rule set, allowing or blocking packets and connections to enforce a security boundary. Firewalls range from stateless packet filters to stateful inspection devices and next-generation appliances that perform deep packet inspection and application awareness. They are a foundational component for segmenting trusted and untrusted networks.
Overview
- Firewalls inspect traffic at the perimeter or between internal zones and decide, per packet or per connection, whether it conforms to policy.
- They evolved from simple packet filters to stateful inspection, which tracks connection state, and to next-generation firewalls that understand applications and users.
- Firewalls are deployed as dedicated hardware, virtual appliances or host-based software.
Key aspects
- Packet filtering on addresses, ports and protocols.
- Stateful inspection that correlates packets to established sessions.
- Deep packet inspection and application-layer awareness in next-generation devices.
- Integration with VPN termination, logging and threat intelligence feeds.
Applications
- Perimeter defence between an organisation and the public internet.
- Internal Network Segmentation to contain lateral movement.
- Host-based protection on servers and endpoints.
- Cloud security groups and virtual firewalls in Cybersecurity architectures.